6.3 KiB
Native DNS Client completion probe
dns-client-probe advances #386 with a fixed benign native DNS lookup and correlation to Windows event 3008. It does not implement a Sigma rule test. Sysmon is excluded. Windows DNS Client Operational logging and Dnscache must already be enabled/running; the command never changes DNS configuration, channel settings, audit policy or service state.
# Observe prerequisites only. Choose a resolver you are authorized to query.
./WELA.ps1 dns-client-probe -DnsClientProbeResolver 192.0.2.53
# Explicit network operation; use a NEW local output directory.
./WELA.ps1 dns-client-probe -DnsClientProbeAction Run `
-DnsClientProbeResolver 192.0.2.53 `
-DnsClientProbeOutputPath C:\WelaEvidence\dns-client-01
The example address is documentation-only: replace it with an approved resolver. Plan creates no files and sends no probe lookup. Run generates exactly one application request for wela-<random-guid>.wela.test. type A; .test is reserved for DNS testing by RFC 2606. There is no caller-selected domain, record type or application connection to a returned address. A same-engine 64-bit worker uses synchronous DnsQueryEx with one explicit IPv4 DNS server, TCP port 53, recursion disabled, cache bypass, no hosts/local-name/NetBT/multicast fallback, fully qualified naming and IDN disabled. DNS retry/internal processing and normal response caching are OS behavior; this is not a promise of one wire packet, cache immutability or resolver-side enforcement. The query name, selected resolver and exact flags are retained. Only canonical unicast IPv4 literals are accepted; there is no hostname or configurable port.
The bounded worker has twenty seconds to finish. Parent/worker timestamps use GetSystemTimePreciseAsFileTime, with no coarse-clock fallback or positive-match time padding. Terminating the worker does not prove cancellation of DNS service or network work; timed-out completion remains unverified. The separate event wait defaults to fifteen seconds (-DnsClientProbeTimeoutSeconds 1..30). Native status 0 (A answers), 9003 (NXDOMAIN) and 9501 (no records) are reviewed completion outcomes. A negative response is not reported as successful name resolution. Missing events, unknown outcomes/versions/types, caps, token or configuration/source drift and incomplete reads remain Unverified with a nonzero exit. No setup is automatically performed to make the test pass.
Evidence includes observed build/patch/role, token and same-engine context, exact provider GUID, live event/version/field types and template hashes, original pinned rule hashes, channel metadata, a pre-query record boundary, bounded original worker JSON (also retained if its validation fails), worker timestamps/status/answers and hashed original matched XML. Matching requires event 3008 version 0 on Microsoft-Windows-DNS-Client/Operational, source computer, unique query name/type, native completion status, requested option bits, record boundary and operation time. The emitter PID is retained in original XML; it may belong to the DNS service broker, so it is not assumed to equal the requesting worker PID. This correlation does not prove exclusive request attribution, the wire destination, DNSSEC validation or absence of simultaneous unrelated events. Full caller token snapshots bracket actual query/event I/O and are compared before final metadata inventory; the worker has its own exact before/after token checks. Metadata inventories are outside this interval because DISM and channel inspection may temporarily adjust privileges. The native read is limited to this random query name, record boundary and last sixty seconds; any retained candidate outside the exact operation interval is diagnostic only. Native event-query status is retained separately from its records. Artifact hashes detect byte changes; they are not signatures or historical host authentication.
PrerequisitesObserved means only that Plan observed supported metadata. NativeDnsLookupObserved means that a native completion and matching local event were observed. Neither proves forwarding, downstream parsing, detection execution or retention capacity. In particular, all six pinned DNS Client rules refer to Microsoft-Windows-DNS Client Events/Operational, a different channel string. WELA retains that mismatch and does not rewrite it. ReadyRuleCredit remains 0; there is no six-rule Sigma uplift.
Native acceptance uses a separately opt-in fixture on disposable GitHub-hosted workgroup Server 2022/2025 under Windows PowerShell 5.1 and PowerShell 7. The fixture refuses an existing DNS role, installs its own standalone role, creates authoritative wela.test with a wildcard A record to 192.0.2.1, and queries only loopback. It temporarily enables the Client channel if needed, restores its exact original settings, checks audit policies, removes its owned zone/records and removes only newly installed DNS features. Feature removal may require VM disposal rather than a live reboot; the cleanup receipt records that boundary. Fixture setup is not part of the product. Windows 11, domain-joined/DC/ADCS hosts and external resolver/network behavior still require their own acceptance evidence.
The P/Invoke entry point is exactly DnsQueryEx, preventing Unicode suffix probing. The server-address buffer follows Microsoft’s DNSAsyncQuery sample: one element, zero aggregate family, and the sockaddr default DNS port.
Native API references: DnsQueryEx, DNS_QUERY_REQUEST, DNS_ADDR_ARRAY, DNS query flags, and the Microsoft Windows SDK declarations.